US12373842B2ActiveUtilityA1

System and method for identifying suspicious destinations

Assignee: ROYAL BANK OF CANADAPriority: Jan 31, 2020Filed: Jul 9, 2024Granted: Jul 29, 2025
Est. expiryJan 31, 2040(~13.5 yrs left)· nominal 20-yr term from priority
G06Q 20/4014H04L 63/102H04L 63/0876G06Q 20/4016H04L 63/1483
69
PatentIndex Score
0
Cited by
6
References
19
Claims

Abstract

Transaction destinations are identified by identifying requests for a login page of a web server for a financial institution and determining a referring website for each of the requests; classifying the referring websites into classes, each of the classes having a risk rating; identifying logins to access the web server and determining a user associated with each login; associating each of the logins with one of the requests and the referring website for that request; for each of the users, identifying transactions occurring within a time period from when the login was initiated; for each of the transactions occurring within the time period, associating a transaction destination of that transaction with the referring website for that login; and assigning a risk rating to each of the transaction destinations based at least in part on a risk rating of the class of the associated referring website.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A computer-implemented method for facilitating electronic financial transactions, the method performed by a web server, the method comprising:
 identifying requests for a login page of the web server, wherein the requests include HTTP requests; 
 upon identifying the requests, determining a referring website for each of the identified requests based on an HTTP referrer header of each of said requests, said HTTP referrer header including an address of said referring website; 
 scanning, by a site classifier, each of said referring websites to extract keywords from each respective referring website; 
 identifying, by said site classifier using natural language processing, an industry of each respective referring website; 
 classifying the referring websites into classes based on a classification system, each of the classes having a risk rating; 
 identifying logins to access the web server; 
 upon identifying the logins, determining a user associated with each of the logins; 
 associating each of the logins with one of the identified requests and with the referring website for that identified request; 
 for each of the users, identifying transactions occurring within a time period from when the one of the logins was initiated; 
 for each of the transactions occurring within the time period, associating a transaction destination of that transaction with the referring website for that one of the logins; 
 assigning a risk rating to each of the transaction destinations based at least in part on a risk rating of the class of the associated referring website; and 
 permitting or blocking an electronic financial transaction of the transactions occurring within the time period based on the risk rating of the transaction destination associated with that transaction. 
 
     
     
       2. The computer-implemented method of  claim 1 , wherein the determining the referring website comprises extracting an identifier of the referring website web server logs from the financial institution. 
     
     
       3. The computer-implemented method of  claim 1 , wherein the associating each of the logins with one of the requests and the referring website for that request is based at least in part on comparing a time stamp of the login and a time stamp of the request. 
     
     
       4. The computer-implemented method of  claim 1 , wherein the associating each of the logins with one of the requests and the referring website for that request is based at least in part on a cookie upon login linking an account of the user with a browser of the user. 
     
     
       5. The computer-implemented method of  claim 1 , wherein the determining the user associated with each login is based at least in part on an IP address in a web server log. 
     
     
       6. The computer-implemented method of  claim 1 , wherein the determining the user associated with each login is based at least in part on an IP address in a HTTP request. 
     
     
       7. The computer-implemented method of  claim 1 , further comprising, grouping users from a common class of the referring websites and identifying, for each of the groups of users, a common transaction destination. 
     
     
       8. The computer-implemented method of  claim 7 , wherein the common transaction destination is identified from the destinations containing a common word. 
     
     
       9. The computer-implemented method of  claim 1 , wherein the time period is between ten and thirty minutes. 
     
     
       10. The computer-implemented method of  claim 9 , wherein the time period is twenty minutes. 
     
     
       11. The computer-implemented method of  claim 1 , wherein the risk ratings of the classes are based at least in part on a whitelist of websites. 
     
     
       12. The computer-implemented method of  claim 1 , wherein the transaction destination of at least one of the transactions is an identification of an entity. 
     
     
       13. The computer-implemented method of  claim 1 , wherein the transaction destination of at least one of the transactions is a bank account. 
     
     
       14. The computer-implemented method of  claim 1 , further comprising identifying additional transactions that send funds to one or more of the transaction destinations. 
     
     
       15. The computer-implemented method of  claim 14 , further comprising assigning a risk rating to the additional transactions based at least in part on the risk ratings of the transaction destinations. 
     
     
       16. The computer-implemented method of  claim 1 , further comprising for each of the transactions, identifying a transaction type and assigning a risk rating to the transaction type based at least in part on the risk rating of the transaction destination. 
     
     
       17. The computer-implemented method of  claim 1 , wherein said generating classifications is based on said classification system and said industry. 
     
     
       18. A computer system comprising:
 a processor; and 
 a memory in communication with the processor, the memory storing instructions that, when executed by the processor cause the processor to perform the method of  claim 1 . 
 
     
     
       19. A non-transitory computer-readable medium having computer executable instructions stored thereon for execution by one or more computing devices, that when executed perform the method of  claim 1 .

Join the waitlist — get patent alerts

Track US12373842B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.